Cl0p Ransomware Group Claims Data Theft from Shell, Philips, and Others

Cl0p Ransomware Group Claims Data Theft from Shell, Philips, and Others

First seen 14 Aug 2026, 11:53 UTC ChannelnewsasiaPravda.UaTechnaduThenextwebBleepingcomputer+4 86% similarity 76.0

Article Content

Browse articles
ThreatCluster

The Cl0p ransomware group has claimed responsibility for a significant data breach affecting nearly 50 companies, including Shell, Philips, General Electric, and Fiserv. The hackers allege to have stolen 89GB of data from Shell and 13.5GB from Philips, including sensitive engineering documents and project plans. The attacks exploit a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM software, allowing for unauthenticated remote code execution. Both Shell and Philips have confirmed attempts to breach their systems and are currently investigating the incidents. The Ransomware Information Sharing and Analysis Center (Ransom-ISAC) has issued warnings about the ongoing exploitation of these vulnerabilities. The attackers utilize a double extortion strategy, threatening to release stolen data if their demands are not met. As of now, no samples of the stolen data have been released by Cl0p.

Key Points: • Cl0p claims to have stolen 89GB from Shell and 13.5GB from Philips. • The attacks exploit a critical vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569). • Both Shell and Philips are investigating the breaches, which may affect nearly 50 companies.

ThreatCluster AI How this analysis works

Timeline

2026-06-18
CVE-2026-12569 published
A critical remote code execution vulnerability in PTC Windchill and FlexPLM was disclosed.
ransom-isac.com
2026-06-25
CVE-2026-12569 added to CISA KEV
CISA confirmed active exploitation of the vulnerability in attacks against organizations.
ransom-isac.com
2026-08-12
Cl0p claims mass data theft
Cl0p announced the theft of data from nearly 50 companies, including Shell and Philips, via their website.
Channelnewsasia
2026-08-14
Shell and Philips confirm investigations
Both companies acknowledged attempts to breach their systems and are investigating the incidents.
Bleepingcomputer
2026-08-14
Ransom-ISAC issues warning
Ransom-ISAC warned about the ongoing exploitation of vulnerabilities in PTC software by Cl0p.
ransom-isac.com

Community

Browse all →